Jobs · Information Technology

Director of Information Security

Sorren · United States · 3 wk ago
RemoteRemoteInformation TechnologyFull-time

About the Firm

Sorren is a top 50 national advisory firm that blends deep expertise with a human-first approach. We work with people, building lasting relationships and delivering strategic solutions in accounting, assurance, tax, advisory, and private client services. Our culture fosters collaboration, innovation, and professional growth, ensuring every team member has the support and opportunities to thrive. We offer a high-performing yet balanced work environment where career development and personal well-being go hand in hand.

Your Journey

Team members support the firm by delivering timely, accurate work and maintaining clear communication. They take ownership of their development, seek feedback, and build strong relationships. By managing responsibilities effectively and aligning efforts with firm values, they establish a foundation for long-term success and growth. All team members are expected to excel in Relationships, Communication, Quality Service, Operational Excellence, and Innovation & Growth.

Responsibilities

  • Develop, maintain, and execute the firm’s information security program, roadmap, and annual priorities in alignment with business objectives, client obligations, and regulatory expectations.
  • Define the security configuration and hardening standards for Microsoft 365 and Entra ID and work with the infrastructure team to ensure they are met.
  • Set the AV and EDR configuration baseline and ensure security alerting and reporting scale as the firm grows.
  • Define and implement data protection controls across platforms, including classification, retention, encryption, and DLP.
  • Set email filtering and security posture standards and work with the infrastructure team to ensure they are met.
  • Oversee firewall and network-device patch and update compliance.
  • Maintain security policies, technical standards, controls, exceptions, and mature how the firm audits against them.
  • Lead risk assessments, control reviews, and security planning activities across the firm’s infrastructure, applications, endpoints, and cloud services, including identifying risks, prioritizing remediation, tracking corrective actions, and validating closure.
  • Own the risk register and tracking, and run security and vendor risk assessments as the practice matures.
  • Build and run the firm’s GLBA and FTC Safeguards program, accounting for other requirements such as HIPAA, PCI DSS, and state privacy laws (e.g., CCPA and CPRA).
  • Support client security reviews, cyber insurance requirements, and regulatory or contractual compliance efforts by preparing evidence, documenting controls, and coordinating remediation plans.
  • Set up recurring system access reviews and support internal and external audit needs, including evidence collection.
  • Maintain the incident response plan and be the point person for incident response activities, including communication, coordinating external responders, and documentation.
  • Plan and facilitate periodic incident response tabletop exercises and post-exercise improvement activities.
  • Run and coordinate vulnerability scans and penetration tests and track remediation to closure.
  • Own the security awareness and phishing simulation program, including strategy, reporting, and continuous improvement.
  • Evaluate, direct, and hold managed-security and security-tool vendors accountable for results, while continuously assessing the effectiveness of current security partnerships and recommending changes where appropriate.
  • Conduct security and risk assessments of proposed software, services, and vendor relationships as part of the software request and approval process.
  • Take part in security due diligence on acquisition targets and document their security posture to inform integration.
  • Maintain awareness of evolving cyber threats, regulatory developments, and leading practices relevant to professional services and accounting firms, and translate them into practical improvements.

Requirements

  • 7+ years of progressive IT and security experience, including 3 or more years hands-on in information security.
  • Proven ability to plan security controls and implement them yourself.
  • Deep hands-on experience securing Microsoft 365 and Entra ID (Conditional Access, MFA, Microsoft Defender, mail-flow, and email authentication) and managing endpoints with Intune.
  • Practical experience with EDR and AV, vulnerability scanning, access reviews, and coordinating incident response.
  • A track record of delivering results through managed-security and vendor partners, including evaluating them, directing their work, and holding them accountable.
  • Working knowledge of regulatory and compliance requirements for financial or professional services data, including GLBA and FTC Safeguards and general privacy and compliance frameworks.
  • Experience maintaining security policies and a risk register and turning them into implemented controls.
  • Strong communication and collaboration skills, with the ability to coordinate across Infrastructure, Support, and business teams to get changes done.

Preferred Qualifications

  • Experience in professional services, accounting, or another regulated, financial-data environment.
  • Experience integrating or standardizing security across a multi-location or acquisitive (M&A) organization.
  • Familiarity with hosted or virtual desktop platforms and the vendor management that goes with them.
  • Relevant certifications such as CISSP, CISM, CISA, CRISC, Microsoft security certifications, or similar credentials.

Benefits

  • Generous paid time off
  • Comprehensive medical, dental, and vision coverage, plus life and disability insurance
  • 401(k) retirement savings plan
  • Paid holidays, including a firmwide winter break (December 24 – January 1)
  • Paid parental leave (available after one year of service)
  • Mentorship and career development programs
  • CPA exam support to help you succeed on the path to licensure
  • Firm-sponsored events and spontaneous team activities
  • Celebrations to mark milestones like the end of busy season and the holidays

Benefits are available to full-time employees regularly scheduled to work at least 30 hours per week.

Similar jobs

Director of Information Security

IDEA Public SchoolsTexas, United States· 1 mo ago
RemoteInformation Technology$108k–$129k/yrapply on careers.ideapublicschools.org